CVE-2018-1721: High severity ibm cognos analytics vulnerability
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cause the web server to make HTTP requests to arbitrary domains. IBM X-Force ID: 147369.
Other sources
IBM Cognos Analytics is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cause the web server to make HTTP requests to arbitrary domains.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-1721.
What software is affected by CVE-2018-1721?
IBM Cognos Analytics 11.0 and 11.1 are affected by CVE-2018-1721.
What is the severity of CVE-2018-1721?
The severity of CVE-2018-1721 is high.
What is the CWE ID for CVE-2018-1721?
The CWE ID for CVE-2018-1721 is CWE-91.
How can an attacker exploit CVE-2018-1721?
A remote attacker could exploit CVE-2018-1721 to expose sensitive information or cause the web server to make HTTP requests to arbitrary domains.